Visualização normal

Antes de ontemStream principal
  • ✇Malwarebytes
  • StreamRat Android malware spreads through Meta and TikTok ads
    A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections,
     

StreamRat Android malware spreads through Meta and TikTok ads

3 de Setembro de 2026, 13:04

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users.

The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok.

The available data shows the ads’ reach, not the number of downloads or infections, but it demonstrates how quickly paid advertising can put a scam in front of a very large audience.

The ads promoted an Android banking Trojan and infostealer called StreamRat. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to steal usernames and passwords, and allow attackers to control the device remotely.

We often warn people not to click suspicious links in unexpected texts or emails. But malicious advertising is harder to recognize because it appears in the same feeds where people expect to find promotions, videos, and recommendations.

This campaign is a perfect demonstration of why “after-the-fact” ad checks are inadequate when it comes to protecting social media users. Attackers used familiar social media advertising and carefully tailored instructions to turn casual interest in free entertainment into a risky app installation.

How the attack worked

The ad led victims to a website posing as a streaming platform. The site checked whether a visitor was using Android. Non-Android visitors were simply prevented from downloading anything, while Android users were shown an app download option. This is a common way for scammers to concentrate their efforts on devices their malware can infect.

The site also identified whether someone had arrived through Instagram, TikTok, Facebook, or a regular browser. It then displayed instructions suited to that situation, including steps to allow the browser to install apps from “unknown sources.” In other words, this was not a generic malicious download page: It was designed to coach people through the security warnings that would normally make them stop and think.

StreamRat is an Android banking Trojan and infostealer. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to collect usernames and passwords, and enable attackers to operate the device remotely. The researchers also found options to cover the screen with a black page or fake Android update screen. These can distract victims while criminals interact with the phone behind the scenes.

How to stay safe

While this campaign targeted Spanish-speaking people, primarily in Spain, the following guidelines can help anyone avoid similar attacks.

  • Avoid installing Android apps from ads, direct-download websites, social media messages, sponsored search results, or links sent by strangers.
  • Download apps through Google Play whenever possible, and check the developer’s name, reviews, and app history rather than relying on an ad.
  • Before enabling installation from “unknown sources,” read our guide, Sideloading on Android: What it is, why it’s risky, and how to do it more safely.
  • Be very cautious when an app asks for Accessibility access, screen-sharing permission, Device Admin privileges, or permission to become the default launcher. Permissions that don’t line up with the intended use of the app are very suspicious.
  • Use an up-to-date, real-time anti-malware solution on all your devices.

What to do if you installed a suspicious app

If you installed a suspicious APK and granted it Accessibility access, disconnect the phone from Wi-Fi and mobile data. If possible, revoke the app’s Accessibility access and remove it. Use another device to change relevant passwords and contact your bank if you used banking apps on the infected phone. A factory reset may be necessary if you cannot confidently remove the infection.

Malwarebytes for Android detects the components of StreamRat as Android/Trojan.Agent.ACRAEEF8A36H36, Android/Trojan.Agent.ACR02DB0614H7, and Android/Trojan.Dropper.ACR9B7ECE83D1.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  • ✇Cybersecurity News
  • ChatGPT Advertising Revenue Soars Do Son
    Discover how OpenAI's controversial ChatGPT advertising revenue rapidly surpassed a staggering $1 billion annualized run rate, signaling a major strategy shift. Related Posts: Codex Modifies Long Task Management EU Classifies ChatGPT as Search Engine Gemini Notebook Adopts Dynamic Quota System The post ChatGPT Advertising Revenue Soars appeared first on Daily CyberSecurity.
     

ChatGPT Advertising Revenue Soars

Por:Do Son
31 de Agosto de 2026, 22:58

Discover how OpenAI's controversial ChatGPT advertising revenue rapidly surpassed a staggering $1 billion annualized run rate, signaling a major strategy shift.

Related Posts:

The post ChatGPT Advertising Revenue Soars appeared first on Daily CyberSecurity.

Do Smart Monitors Track You? What Buyers Should Know

26 de Agosto de 2026, 15:28

A smart monitor can do far more than display a PC. Built-in apps, ACR, and advertising systems can introduce additional privacy considerations.

The post Do Smart Monitors Track You? What Buyers Should Know appeared first on TechRepublic.

DuckDuckGo Now Blocks Most YouTube Ads Right Inside Its Browser

DuckDuckGo's browser now blocks most YouTube ads by default on supported devices. Here's how it works, which platforms support it, and its limits.
  • ✇Schneier on Security
  • Papa Johns Surveillance-Based Advertising Bruce Schneier
    Papa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceries—and thus more likely to be swayed by a mouth-watering ad. The idea is to reach hungry consumers by “knowing what is in their fridge without being too creepy,” said Carrie Drinkwater, chief investment officer at Carat. To achieve that goal, NBCU and Instacar
     

Papa Johns Surveillance-Based Advertising

1 de Julho de 2026, 07:53

Papa Johns is spying on people’s buying activities to predict when they are low on food:

The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceries—and thus more likely to be swayed by a mouth-watering ad. The idea is to reach hungry consumers by “knowing what is in their fridge without being too creepy,” said Carrie Drinkwater, chief investment officer at Carat.

To achieve that goal, NBCU and Instacart created a custom audience of shoppers who regularly purchase grocery staples on Instacart, such as eggs, milk, meat and produce. Based on that data, Papa Johns can determine which days of the week certain consumers are likely to run out of groceries and serve them an ad on NBCU streaming content accordingly. The brand served custom creatives to consumers based on their food preferences—such as whether they buy meat regularly—with QR codes and calls to action such as, “Light on groceries?” or “Empty fridge?”

Back in 2012, we learned (from Target and its campaign that detects when someone is pregnant) that the trick is to hide the knowledge in other, wrong, information. So the way for Papa John’s to not be “too creepy” is to deliberately get it wrong sometimes.

But still, ugh.

  • ✇Malwarebytes
  • Fake virus alerts are invading mobile games
    Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your account is restricted for watching porn!” Some games can be played for free if you agree to watch ads, and in others you can get extra lives, perks, or boosters by watching ads. That’s fine, as long as you’re given a choice and the ads are legitimate. Unfortunately, cybercriminals sometimes manage to buy adv
     

Fake virus alerts are invading mobile games

2 de Junho de 2026, 06:03

Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere:

“Your device is infected!”

“Your iCloud is full!”

“Your account is restricted for watching porn!”

Some games can be played for free if you agree to watch ads, and in others you can get extra lives, perks, or boosters by watching ads. That’s fine, as long as you’re given a choice and the ads are legitimate.

Unfortunately, cybercriminals sometimes manage to buy advertising space and use it to defraud gamers.

Let’s look at some examples.

The iCloud storage scam, or its OneDrive equivalent, is a well-known and long-running scam that claims you need to expand your storage or all your files will be deleted. The websites these messages link to come in many forms, but they all ask for personal and payment details to complete the upgrade.

Restricted account

“Your account has been restricted.
We have detected that your device has been hacked after visiting adult websites.
Solution:
1:Click the “OK” button below;

2:You will be redirected to App Store;

3:Install and open the app, then run the cleanup program.”

This ad is a scam and uses a classic scare tactic. It falsely claims your device has been hacked and tries to pressure you into clicking “OK” and installing a cleanup app.

Messages like this sometimes claim to be from your ISP, a “Security Department,” or a generic “Safety Center.”

 Fake Apple security alert

“Apple Security Alert
8 viruses have been detected on your iPhone. Now iOS is damaged by 72%. Further damage to the system will result in device lockup and loss of all data within two minutes.
Please click the button below to remove all viruses.”

This is another fake warning, commonly used by scammers to trick users into clicking links or downloading unnecessary or harmful software. Apple doesn’t send alerts like this, and these messages use vague threats to get your attention.

What kind of app you’re really installing if you follow the instructions depends on your device and your location. If you’re “lucky,” it’s just adware, but you might just as easily end up with an infostealer.

In many cases, you’ll end up with fleeceware, a type of deceptive mobile app where developers lure users in with short free trials that quickly convert into hidden subscription fees, sometimes costing hundreds of dollars per month. These apps often offer some functionality to stay on the barely legal side of things, but at wildly inflated prices.

How to stay safe

The best response to these messages is simply to ignore them.

Real system alerts come from the OS, not from inside a game window or browser tab. Here’s a simple test: If you can switch apps and the “warning” disappears with the browser/game, it was not a system‑level alert.

Check the destination URLs before proceeding. Apple, Google, and major ISPs use predictable domains. A familiar-looking URL is not proof that a message is legitimate, but if the URL looks suspicious, it should definitely be treated as a scam.


Scam or legit? Scam Guard knows.


You may arrive at something that looks like the official App Store or Google Play Store. Be wary of lookalike app stores and unofficial download sites, but if you are on the real store, the app is generally safer to install. However, it’s still worth checking reviews, permissions, and the developer before proceeding.

Visit the official website of the organization the message claims to be from and log in there. If there’s a genuine problem with your account, storage, or device, you’ll find information about it through official channels.

Use an up-to-date, real-time anti-malware solution on your devices that can detect and block malicious apps.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  • ✇Firewall Daily – The Cyber Express
  • Google Says Gemini Ad Safety Blocked 8.3 Billion Policy-Violating Ads in 2025 Samiksha Jain
    Google has shared new details on how its Gemini ad safety systems are being used to detect and block harmful ads, as online scams continue to grow in scale and complexity. The update points to a sharp rise in malicious advertising activity, with billions of ads removed and millions of advertiser accounts suspended over the past year. The company said its systems blocked more than 8.3 billion ads in 2025, with a large portion linked to scam activity. Nearly 25 million advertiser accounts were
     

Google Says Gemini Ad Safety Blocked 8.3 Billion Policy-Violating Ads in 2025

Gemini Ad Safety

Google has shared new details on how its Gemini ad safety systems are being used to detect and block harmful ads, as online scams continue to grow in scale and complexity. The update points to a sharp rise in malicious advertising activity, with billions of ads removed and millions of advertiser accounts suspended over the past year. The company said its systems blocked more than 8.3 billion ads in 2025, with a large portion linked to scam activity. Nearly 25 million advertiser accounts were also suspended, including millions tied to fraudulent campaigns. The figures highlight the volume of abuse facing large ad platforms and the ongoing challenge of keeping such content in check. [caption id="attachment_111449" align="aligncenter" width="700"]Gemini Ad Safety Image Source: Google[/caption]

Gemini Ad Safety Focuses on Early Detection

A key shift in Gemini ad safety is the focus on stopping harmful ads before they are published. Instead of relying only on keyword-based filters, newer systems are designed to assess intent by analyzing a wide range of signals such as account behavior, campaign patterns, and account history. This approach reflects a broader move across the industry toward earlier detection. By identifying suspicious activity at the submission stage, platforms aim to reduce the number of harmful ads that reach users in the first place. Google said its systems now catch more than 99 percent of policy-violating ads before they are served, although such figures are difficult to independently verify.

Rise of AI-Generated Scam Ads Adds Pressure

The update comes as scammers increasingly use generative AI to create more convincing fake ads. These ads can mimic legitimate businesses, use polished language, and adapt quickly, making them harder to detect using older systems. This shift has put pressure on ad platforms to respond faster. Under the Gemini ad safety framework, many ads are now reviewed instantly at the time they are submitted. This includes Responsive Search Ads, where harmful content can be blocked before going live. At the same time, user reports continue to play a role. Google said it processed significantly more user complaints in 2025 compared to the previous year, allowing faster action when suspicious ads slip through.

Policy Enforcement and Verification Measures Expand

Alongside automated detection, enforcement still relies on Google Ads policies, which define what content and practices are allowed. These rules prohibit areas such as counterfeit goods, dangerous products, and services that enable dishonest behavior, including hacking tools or fake documents. Advertiser verification is another part of the system. By requiring identity checks, platforms attempt to prevent repeat offenders from re-entering under new accounts. While verification can limit abuse, it also depends on how strictly it is enforced and how easily it can be bypassed. The combination of policy enforcement and AI-based detection forms the backbone of the current Gemini ad safety approach.

Accuracy Improves, but Challenges Remain

One issue in ad moderation is the risk of false positives, where legitimate advertisers are flagged or suspended. Google said improvements in its models have reduced incorrect suspensions, suggesting better differentiation between genuine campaigns and misleading ones. Even so, the scale of enforcement raises ongoing questions. Blocking billions of ads indicates both improved detection and the sheer volume of problematic content being submitted. The use of AI on both sides is also shaping the landscape. While platforms use tools like Gemini ad safety to detect abuse, attackers are using similar technologies to create it. This creates a continuous cycle where detection methods need to keep evolving.

Ongoing Effort to Contain Malicious Advertising

The latest figures underline how widespread malicious advertising has become. Scam ads remain a persistent issue, particularly in sectors where users are more likely to engage with offers or financial services. Google’s update suggests progress in identifying and removing harmful content earlier in the process. However, the data also shows that ad platforms are dealing with a high and steady flow of abuse attempts. As Gemini ad safety systems continue to develop, the focus is likely to remain on faster detection, stronger verification, and tighter enforcement. For users, the impact depends on how effectively these measures reduce exposure to scam ads over time.
❌
❌